<< Prev Question Next Question >>

Question 20/111

A web server is running PHP, and a penetration tester is using LFI to execute commands by passing parameters through the URL. This is possible because server logs were poisoned to execute the PHP system ( ) function. Which of the following would retrieve the contents of the passwd file?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (111q)
Question 1: A penetration tester is performing a code review against a w...
Question 2: A penetration tester has gained physical access to a facilit...
Question 3: Which of the following BEST explains why it is important to ...
Question 4: A penetration tester has access to a local machine running L...
Question 5: A penetration tester is performing a remote scan to determin...
Question 6: Consumer-based IoT devices are often less secure than system...
Question 7: A penetration tester is attempting to capture a handshake be...
Question 8: A security consultant finds a folder in "C VProgram Files" t...
Question 9: After successfully exploiting a local file inclusion vulnera...
Question 10: A tester has determined that null sessions are enabled on a ...
Question 11: A penetration tester has been asked to conduct OS fingering ...
Question 12: A penetration tester is utilizing social media to gather inf...
Question 13: An individual has been hired by an organization after passin...
Question 14: A client has scheduled a wireless penetration test. Which of...
Question 15: A penetration tester is performing initial intelligence gath...
Question 16: Which of the following properties of the penetration testing...
Question 17: A client has requested an external network penetration test ...
Question 18: Which of the following exploits a vulnerability associated w...
Question 19: Which of the following types of physical security attacks do...
Question 20: A web server is running PHP, and a penetration tester is usi...
Question 21: Instructions: Analyze the code segments to determine which s...
Question 22: An email sent from the Chief Executive Officer (CEO) to the ...
Question 23: A penetration tester entered the following information into ...
Question 24: During a web application assessment, a penetration tester di...
Question 25: During an internal penetration test, several multicast and b...
Question 26: A penetration tester has been asked to conduct a penetration...
Question 27: During a vulnerability assessment, the security consultant f...
Question 28: A penetration tester is planning to conduct a distributed di...
Question 29: Consider the following PowerShell command: powershell.exe IE...
Question 30: A recent vulnerability scan of all web servers in an environ...
Question 31: A software development team recently migrated to new applica...
Question 32: A company's corporate policies state that employees are able...
Question 33: During an internal network penetration test, a tester recove...
Question 34: A penetration tester is reviewing the following output from ...
Question 35: A penetration tester successfully exploits a system, receivi...
Question 36: A penetration tester was able to enter an SQL injection comm...
Question 37: Click the exhibit button. (Exhibit) Given the Nikto vulnerab...
Question 38: A company planned for and secured the budget to hire a consu...
Question 39: During a penetration test, a tester runs a phishing campaign...
Question 40: During a full-scope security assessment, which of the follow...
Question 41: A penetration tester is testing a banking application and un...
Question 42: An attacker performed a MITM attack against a mobile applica...
Question 43: A penetration tester is performing a code review. Which of t...
Question 44: A penetration tester needs to use Nmap to scan a host with a...
Question 45: A penetration tester ran the following Nmap scan on a comput...
Question 46: A penetration tester has run multiple vulnerability scans ag...
Question 47: Instructions: Analyze the code segments to determine which s...
Question 48: A system security engineer is preparing to conduct a securit...
Question 49: Which of the following attacks is commonly combined with cro...
Question 50: Given the following Python code: a = 'abcdefghijklmnop' a[::...
Question 51: A company contracted a firm specializing in penetration test...
Question 52: A penetration tester is exploiting the use of default public...
Question 53: A consultant is identifying versions of Windows operating sy...
Question 54: A penetration tester reviews the scan results of a web appli...
Question 55: A client's systems administrator requests a copy of the repo...
Question 56: An internal network penetration test is conducted against a ...
Question 57: Which of the following is an example of a spear phishing att...
Question 58: Given the following HTTP response: http/1.0 200 OK Server: A...
Question 59: Which of the following describe a susceptibility present in ...
Question 60: Which of the following BEST protects against a rainbow table...
Question 61: An attacker is attempting to gain unauthorized access to a W...
Question 62: Prior to a security assessment of a company's user populatio...
Question 63: Which of the following documents BEST describes the manner i...
Question 64: A penetration tester is testing a web application and is log...
Question 65: A security guard observes an individual entering the buildin...
Question 66: A client has voiced concern about the number of companies be...
Question 67: After establishing a shell on a target system, Joe, a penetr...
Question 68: A penetration tester wants to script out a way to discover a...
Question 69: A malicious user wants to perform an MITM attack on a comput...
Question 70: D18912E1457D5D1DDCBD40AB3BF70D5D During the exploitation pha...
Question 71: The results of a basic compliance scan show a subset of asse...
Question 72: The scope of a penetration test requires the tester to be st...
Question 73: After gaining initial low-privilege access to a Linux system...
Question 74: A penetration tester is asked to scope an external engagemen...
Question 75: A company hires a penetration tester to determine if there a...
Question 76: When negotiating a penetration testing contract with a prosp...
Question 77: A security team is switching firewall vendors. The director ...
Question 78: A penetration tester runs the following on a machine: (Exhib...
Question 79: A company planned for and secured the budget to hire a consu...
Question 80: When conducting reconnaissance against a target, which of th...
Question 81: A penetration tester has successfully exploited an applicati...
Question 82: Which of the following is an important stakeholder to notify...
Question 83: Joe, a penetration tester, is asked to assess a company's ph...
Question 84: When communicating the findings of a network vulnerability s...
Question 85: A penetration tester locates a few unquoted service paths du...
Question 86: A penetration tester is preparing to conduct API testing Whi...
Question 87: A penetration tester is required to report installed shells ...
Question 88: A software developer wants to test the code of an applicatio...
Question 89: A penetration tester identifies prebuilt exploit code contai...
Question 90: A penetration tester has SSH access to a Linux server that i...
Question 91: A penetration tester calls human resources and begins asking...
Question 92: You are a penetration tester running port scans on a server....
Question 93: A penetration tester compromises a system that has unrestric...
Question 94: While conducting information gathering, a penetration tester...
Question 95: Which of the following is the BEST initial attack against an...
Question 96: A penetration tester has performed a security assessment for...
Question 97: An attacker uses SET to make a copy of a company's cloud-hos...
Question 98: Which of the following tools can be used to perform a basic ...
Question 99: Which of the following CPU register does the penetration tes...
Question 100: A penetration tester discovers SNMP on some targets. Which o...
Question 101: A penetration tester notices that the X-Frame-Optjons header...
Question 102: Which of the following is the BEST way to deploy vulnerabili...
Question 103: A penetration tester is scanning a network for SSH and has a...
Question 104: Click the exhibit button. (Exhibit) A penetration tester is ...
Question 105: A penetration tester executed a vulnerability scan against a...
Question 106: A client is asking a penetration tester to evaluate a new we...
Question 107: A consultant is performing a social engineering attack again...
Question 108: A penetration tester identifies the following findings durin...
Question 109: A penetration test was performed by an on-staff junior techn...
Question 110: An engineer, who is conducting a penetration test for a web ...
Question 111: A recently concluded penetration test revealed that a legacy...